Skip to content

build(deps): bump the production-dependencies group across 1 directory with 13 updates - #458

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/production-dependencies-112bc23461
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/production-dependencies-112bc23461

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 13 updates in the / directory:

Package From To
@ant-design/icons 6.3.2 6.3.4
@fission-ai/openspec 1.11.0 1.13.2
@inquirer/ansi 2.0.7 2.0.8
@inquirer/core 12.0.1 12.0.3
@inquirer/figures 2.0.8 2.0.9
@inquirer/prompts 8.7.0 8.7.2
@inquirer/type 4.1.0 4.1.1
antd 6.6.2 6.6.5
dompurify 3.4.14 3.4.16
marked 18.0.11 18.0.14
mermaid 11.17.2 12.0.0
smol-toml 1.8.0 1.9.0
yaml 2.9.0 2.9.1

Updates @ant-design/icons from 6.3.2 to 6.3.4

Commits

Updates @fission-ai/openspec from 1.11.0 to 1.13.2

Release notes

Sourced from @​fission-ai/openspec's releases.

v1.13.2 - Verify and Windows archive fixes

What's New in v1.13.2

This release makes /opsx:verify report what it actually checked, makes archive reliable on Windows, and fixes workflow guidance across several tools.

Improved

  • Task guidance - Each task group now includes its own tests and documentation updates instead of deferring them to a final group, and onboarding teaches the same rule.
  • Approval prompts - Fast-forward asks for clarification only when context is critically unclear, and onboarding asks you to approve the task breakdown before saving it.
  • Scenario-loss messages - When openspec validate or openspec archive flags a MODIFIED block that drops scenarios, it now also says what the block adds.
  • Codex setup hint - The setup hint is clearer for Codex CLI, IDE, and desktop app users.

Fixed

  • Verify - /opsx:verify no longer reports skipped checks as passing, and no longer tells agents to re-implement a requirement the change removed. Removed requirements pass once the behavior is gone, and renamed requirements are checked against their original behavior.
  • Archive on Windows - Archive no longer leaves .openspec-archive.lock behind, and it finishes instead of rolling back when Windows blocks renaming a change directory.
  • Line endings - Rewriting a CRLF spec, .bashrc, .zshrc, or CLAUDE.md keeps its existing line endings, so Windows users no longer get whole-file diffs.
  • Archive task warnings - Agent-driven archive uses schema-aware task progress, so custom task files and globs still trigger incomplete-task warnings.
  • Artifact outputs - Artifact output patterns with brace expansion or extglob now resolve, while literal filenames still work.
  • /opsx:update - Update can now fill a missing file under a glob artifact that is already partly written, instead of pointing you to a step that could not do it.
  • Workflow schema labels - Workflows no longer display a schema name that openspec list --json does not return.
  • Kilo Code - Commands are generated in .kilo/command/, where Kilo Code reads them. openspec init and legacy cleanup remove the files OpenSpec generated in .kilocode/workflows/, matched by their known file names (including copies you edited), and leave other files in place.
  • Continue - Continue commands no longer lead local models to call a tool named after the active workflow.
  • Validation - validate --strict no longer treats a Spanish or Portuguese Purpose starting with "Todo" as a placeholder.
  • Codex update - openspec update --force now exits non-zero when it cannot replace a legacy-only Codex install.

New Contributors

Full Changelog: Fission-AI/OpenSpec@v1.13.1...v1.13.2

v1.13.1 - Hardened CLI, safer archives

What's New in v1.13.1

This release makes OpenSpec safer to run in repositories you have not reviewed yet, and makes archive, validation, and the agent workflows more predictable.

Improved

  • Security hardening - OpenSpec is safer in a freshly cloned repository. A config.yaml value can no longer inject directives into agent instructions, crafted files can no longer hang openspec update or openspec archive, and a repository's .npmrc can no longer redirect the update check.
  • Next step in openspec status - Status now ends with a Next: line naming the exact command that moves the change forward, so resuming a change no longer means knowing the workflow by heart.
  • Profile-aware skills - Generated skills and commands name only the workflows your profile installs, and they match natural phrasing such as "openspec propose" or "do an openspec apply".
  • Project check - Workflows confirm the project has run openspec init before writing anything, and never create an openspec/ folder as a side effect.

... (truncated)

Changelog

Sourced from @​fission-ai/openspec's changelog.

1.13.2

Patch Changes

  • #1940 0b5ce44 Thanks @​clay-good! - Keep fast-forward clarification guidance and onboarding task approval consistent across generated skills and commands. Fast-forward now asks only when context is critically unclear, while onboarding asks users to approve the task breakdown before saving it and separately asks whether to begin implementation.

  • #1926 f2812f6 Thanks @​kevin9327! - ### Bug Fixes

    • Archive — When Windows EPERM blocks renaming a change directory that still has children, copy from the original source instead of requiring a staging rename that fails the same way. That lets archive finish instead of rolling back the spec write and leaving an empty capability directory git cannot see. A staging failure that is not EPERM/EXDEV still leaves the source untouched.

      The source of that unstaged copy is still the live change directory, which the archive claim does not cover, so cleanup removes only the entries it copied and verified rather than whatever is present when it runs. A file written in that window is left alone and the complete destination is retained for recovery, instead of being deleted without ever reaching the archive.

      An edit to a file that was already verified is covered too. Cleanup claims each entry with an atomic rename before reading it, then compares what it claimed against the copy. A rewrite that lands first is caught by that comparison and the file is put back; one that lands after creates a new file at the original path, which is never deleted. Either way the newer bytes stay on disk and archive reports the move as incomplete rather than succeeding with the older copy.

      Rollback of a newly created spec now also prunes the capability directory it created — and only that one. An empty capability directory that was already there is left in place with its own permissions.

  • #1795 fb1b876 Thanks @​runsonmypc! - Archive workflows now use schema-aware task progress from openspec list --json, so custom task files and globs still trigger incomplete-task warnings.

  • #1885 fd56e12 Thanks @​philo-x! - Fix artifact output resolution to recognize brace expansion and extglob patterns while preserving literal output filenames and confining brace-expanded paths to the change directory.

  • #1964 7ac58dc Thanks @​clay-good! - Continue commands now open with an instruction to follow the active OpenSpec workflow directly, so local models no longer try to call a tool named after it (#1944).

  • #1964 7ac58dc Thanks @​clay-good! - Generate Kilo Code commands in .kilo/command/, the directory Kilo Code reads, instead of .kilocode/workflows/ (#1938). openspec init and legacy cleanup remove the workflow files OpenSpec generated there, matched by their known file names (including copies you edited), and leave files with other names in place.

  • #1958 1d35e90 Thanks @​clay-good! - Preserve a file's existing line endings when rewriting it, so Windows users no longer get whole-file diffs. Applying a delta to a CRLF spec (the default on a Windows checkout with core.autocrlf=true) rewrote the file to LF, turning a one-requirement change into a diff that touched every line. openspec archive now writes the spec back with the convention it already used; a spec that does not exist yet is still written with LF.

    The same fix covers marker-managed files: installing or updating shell completions in a CRLF .bashrc or .zshrc no longer leaves the file with mixed endings, which bash reports as $'\r': command not found.

    Removing a managed block is fixed the same way: the blank-line collapse in removeMarkerBlock rebuilt its separator as a bare LF, so cleaning up legacy artifacts left a lone LF inside an otherwise-CRLF CLAUDE.md or rc file. Both write paths now read the file the same way, by dominant ending, so one stray CRLF in an otherwise-LF file no longer pulls the whole rewrite to CRLF.

    scripts/pack-version-check.mjs now spawns npm through cross-spawn, so the release guard can run on Windows, where npm is npm.cmd and cannot be resolved by execFile.

  • #1912 8826c0c Thanks @​Tyagiquamar! - Fix validate --strict reporting PURPOSE_IS_PLACEHOLDER for a Purpose that opens with the ordinary word "Todo" followed by prose, as in Spanish ("Todo el…") and Portuguese ("Todo o…") specs (#1897).

    • Case now separates the marker from the word. TBD/TODO in capitals is still a placeholder marker whatever follows it, so TODO write this later is still reported.
    • In any other case it counts as a marker only when followed by the end of the Purpose, a line break, or marker punctuation (todo -, tbd.), so an authored Spanish or Portuguese sentence is not reported.
  • #1744 5b55263 Thanks @​javigomez! - Clarify the Codex setup hint for CLI, IDE, and desktop app users.

  • #1809 a5ceea3 Thanks @​ryandemelo! - Say what a MODIFIED block adds when the scenario-loss guard fires (#1809). openspec validate and openspec archive already named the scenarios a block omits. They now also print how many scenarios each side has and which ones the block introduces, capped at three names, so a rename and a truncation read differently without opening either file. The guard catches exactly what it did before, and no exit code changes.

  • #1731 d6bdef6 Thanks @​runsonmypc! - Stop workflows from displaying schema names that openspec list --json does not return. Update and continue no longer fabricate a spec-driven picker label, while bulk archive and explore describe only the change fields the list command actually provides.

  • #1955 ed5d386 Thanks @​clay-good! - Task guidance now requires each task group to land its own tests and documentation updates instead of deferring them to a trailing group. The onboarding walkthrough teaches the same rule, and the published schema reference no longer quotes stale instruction text.

  • #1939 a64303f Thanks @​clay-good! - Return a nonzero exit status when openspec update --force cannot replace a legacy-only Codex installation.

  • #1733 72fbe4c Thanks @​runsonmypc! - Let /opsx:update fill a missing file under an already-satisfied glob artifact. A glob artifact is complete once one file matches it, and /opsx:continue only picks up ready artifacts, so the previous "point the user to /opsx:continue" handoff was unreachable and the missing file could never be created through the documented flow.

  • #1962 3364146 Thanks @​ryandemelo! - Stop /opsx:verify from reporting a correctly removed requirement as missing. Verify now reads which delta section each requirement sits under: ADDED and MODIFIED requirements are checked for an implementation as before, a REMOVED requirement passes once its behavior is gone and is flagged only while it is still present, and the old name of a RENAMED requirement is no longer reported as missing.

... (truncated)

Commits
  • db23097 Version Packages (#1953)
  • 7ac58dc chore(changeset): track Kilo Code and Continue fixes for 1.13.2 (#1964)
  • 3364146 fix(verify): stop reporting removed requirements as missing (#1962)
  • 072de6b fix(verify): do not report unverified dimensions as passing (#1732)
  • d6bdef6 fix(workflows): stop reading schema from list output (#1731)
  • fb1b876 fix(archive): use schema-aware task progress in workflows (#1795)
  • f2812f6 fix(archive): copy without staging when Windows EPERM blocks rename (#1926)
  • 72fbe4c fix(update): close the dead end for partially populated glob artifacts (#1733)
  • ed5d386 fix(tasks): keep tests and docs inside each task group (#1955)
  • 1d35e90 fix(windows): preserve a file's existing line endings on rewrite (#1958)
  • Additional commits viewable in compare view

Updates @inquirer/ansi from 2.0.7 to 2.0.8

Release notes

Sourced from @​inquirer/ansi's releases.

@​inquirer/figures@​2.0.8

No source changes. Bumped to keep in lockstep with the @inquirer/* release train.

Commits
  • 5748bd9 chore: Publish new release
  • 269ae73 fix: pin @​inquirer/type exactly in published manifests
  • 927d6dd fix(@​inquirer/testing): keep keypress simulation working under TERM=dumb
  • 2d813b1 chore(deps): Bump @​humanfs/node from 0.16.6 to 0.16.8 (#2245)
  • 7affbc9 chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (#2243)
  • 56db989 chore(deps-dev): Bump oxfmt in the formatting group (#2242)
  • 8e6bc3c chore(deps-dev): Bump the linting group with 2 updates (#2241)
  • 427b7a1 chore(deps-dev): Bump the testing group with 3 updates (#2240)
  • 51ac389 chore: Publish new release
  • 0f1718e feat(@​inquirer/password): add ctrl+t toggle to reveal password
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​inquirer/ansi since your current version.


Updates @inquirer/core from 12.0.1 to 12.0.3

Release notes

Sourced from @​inquirer/core's releases.

@​inquirer/core@​12.0.3

What's new

  • Fixed a race where keystrokes batched in the same tick as the key that settled a prompt could still reach useKeypress handlers after the prompt was done, cancelled, or aborted. Hook effects are now cleared in the synchronous settlement path (#2255, closes #1816).
  • Prompts created with an already-aborted signal now run the terminal cleanup (restore the cursor, close the readline interface, end the output stream) instead of leaking them (#2255).
Commits
  • cbdb34b chore: Publish new release
  • 8340d2d fix(@​inquirer/core): clear hook effects before settling prompts
  • 2475e07 test(@​inquirer/core): cover hook cleanup error semantics
  • 15cd8d3 fix(confirm): ignore surrounding whitespace in answers
  • 9cb0da6 chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9
  • 1c750bc chore(deps-dev): Bump the build group with 3 updates (#2251)
  • 81f1525 chore(deps-dev): Bump @​types/node in the types group (#2252)
  • 7c27f26 chore(deps-dev): Bump oxfmt in the formatting group (#2249)
  • 6119088 chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#2250)
  • 0d167c0 chore(deps-dev): Bump the linting group with 4 updates (#2248)
  • Additional commits viewable in compare view

Updates @inquirer/figures from 2.0.8 to 2.0.9

Commits
  • 5748bd9 chore: Publish new release
  • 269ae73 fix: pin @​inquirer/type exactly in published manifests
  • 927d6dd fix(@​inquirer/testing): keep keypress simulation working under TERM=dumb
  • 2d813b1 chore(deps): Bump @​humanfs/node from 0.16.6 to 0.16.8 (#2245)
  • 7affbc9 chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (#2243)
  • 56db989 chore(deps-dev): Bump oxfmt in the formatting group (#2242)
  • 8e6bc3c chore(deps-dev): Bump the linting group with 2 updates (#2241)
  • 427b7a1 chore(deps-dev): Bump the testing group with 3 updates (#2240)
  • 51ac389 chore: Publish new release
  • 0f1718e feat(@​inquirer/password): add ctrl+t toggle to reveal password
  • Additional commits viewable in compare view

Updates @inquirer/prompts from 8.7.0 to 8.7.2

Release notes

Sourced from @​inquirer/prompts's releases.

@​inquirer/prompts@​8.7.2

What's new

  • Fixed a race where keystrokes batched in the same tick as the key that settled a prompt could still reach keypress handlers after the prompt was done, cancelled, or aborted (@inquirer/core, #2255, closes #1816).
  • confirm() now trims surrounding whitespace from answers before matching yes/no keywords (@inquirer/confirm, #2254).

Included

  • @inquirer/checkbox@^5.2.5
  • @inquirer/confirm@^6.3.2
  • @inquirer/editor@^5.3.3
  • @inquirer/expand@^5.1.5
  • @inquirer/input@^5.1.6
  • @inquirer/number@^4.2.3
  • @inquirer/password@^5.2.2
  • @inquirer/rawlist@^5.3.5
  • @inquirer/search@^4.3.3
  • @inquirer/select@^5.2.5

@​inquirer/prompts@​8.7.1

What's new

  • All bundled prompts now pin @inquirer/type to an exact version in their published manifests. Since these type definitions leak into consumers' tsc runs, a semver range on the types-only dependency could break downstream TypeScript builds without any change to Inquirer.js itself (#2247, fixes #2244).

Included

  • @inquirer/checkbox@^5.2.4
  • @inquirer/confirm@^6.3.1
  • @inquirer/editor@^5.3.2
  • @inquirer/expand@^5.1.4
  • @inquirer/input@^5.1.5
  • @inquirer/number@^4.2.2
  • @inquirer/password@^5.2.1
  • @inquirer/rawlist@^5.3.4
  • @inquirer/search@^4.3.2
  • @inquirer/select@^5.2.4
Commits
  • cbdb34b chore: Publish new release
  • 8340d2d fix(@​inquirer/core): clear hook effects before settling prompts
  • 2475e07 test(@​inquirer/core): cover hook cleanup error semantics
  • 15cd8d3 fix(confirm): ignore surrounding whitespace in answers
  • 9cb0da6 chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9
  • 1c750bc chore(deps-dev): Bump the build group with 3 updates (#2251)
  • 81f1525 chore(deps-dev): Bump @​types/node in the types group (#2252)
  • 7c27f26 chore(deps-dev): Bump oxfmt in the formatting group (#2249)
  • 6119088 chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#2250)
  • 0d167c0 chore(deps-dev): Bump the linting group with 4 updates (#2248)
  • Additional commits viewable in compare view

Updates @inquirer/type from 4.1.0 to 4.1.1

Commits
  • 5748bd9 chore: Publish new release
  • 269ae73 fix: pin @​inquirer/type exactly in published manifests
  • 927d6dd fix(@​inquirer/testing): keep keypress simulation working under TERM=dumb
  • 2d813b1 chore(deps): Bump @​humanfs/node from 0.16.6 to 0.16.8 (#2245)
  • 7affbc9 chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (#2243)
  • 56db989 chore(deps-dev): Bump oxfmt in the formatting group (#2242)
  • 8e6bc3c chore(deps-dev): Bump the linting group with 2 updates (#2241)
  • 427b7a1 chore(deps-dev): Bump the testing group with 3 updates (#2240)
  • See full diff in compare view

Updates antd from 6.6.2 to 6.6.5

Release notes

Sourced from antd's releases.

6.6.5

  • 🐞 Fix numeric 0 content rendering across Result, message, notification, Avatar, Modal, Descriptions, and Form.Item. #59153 #59125 #59289 @​bhumin18 @​nrps9909 @​QDyanbing
  • Upload
    • 🐞 Fix Upload.Dragger custom style.height being overridden when the height prop is not set. #59319 @​dogledogle
    • ♿ Fix Upload file names being focusable as buttons when no preview action is available. #59295 @​QDyanbing
  • Transfer
    • 🐞 Fix Transfer calling a stale onSelectChange callback after it is replaced or removed. #59307 @​yunfeizhu
    • 🐞 Fix Transfer footer callbacks not receiving direction when using rest parameters. #59303 @​QDyanbing
  • 🐞 Fix Avatar not retrying image loading after srcSet changes. #59297 @​QDyanbing
  • 🐞 Fix Anchor scrolling and Table and Transfer range selection using stale values after updates. #59308 @​QDyanbing
  • 🐞 Fix Select inconsistent single and multiple heights after customizing global fontSize or lineHeight. #59298 @​zombieJ
  • 🤖 Fix Tooltip, Popover, Popconfirm, and Slider TypeScript definitions accepting unsupported rc Tooltip props. #59288 @​QDyanbing
  • 🛎 Fix Drawer not warning that destroyOnClose is deprecated. #59299 @​dogledogle

  • 🐞 修复 Result、message、notification、Avatar、Modal、Descriptions 和 Form.Item 无法正确渲染数值 0 内容的问题。#59153 #59125 #59289 @​bhumin18 @​nrps9909 @​QDyanbing
  • Upload
    • 🐞 修复 Upload.Dragger 未设置 height 属性时自定义 style.height 被覆盖的问题。#59319 @​dogledogle
    • ♿ 修复 Upload 没有可用预览操作时文件名仍可作为按钮聚焦的问题。#59295 @​QDyanbing
  • Transfer
    • 🐞 修复 Transfer 在替换或移除 onSelectChange 后仍调用旧回调的问题。#59307 @​yunfeizhu
    • 🐞 修复 Transfer 使用剩余参数的 footer 回调无法获取 direction 的问题。#59303 @​QDyanbing
  • 🐞 修复 Avatar 图片加载失败后更新 srcSet 无法重新加载的问题。#59297 @​QDyanbing
  • 🐞 修复 Anchor 滚动及 Table 和 Transfer 范围选择在更新后仍使用旧值的问题。#59308 @​QDyanbing
  • 🐞 修复 Select 自定义全局 fontSize 或 lineHeight 后单选与多选高度不一致的问题。#59298 @​zombieJ
  • 🤖 修正 Tooltip、Popover、Popconfirm 和 Slider 的 TypeScript 类型定义,避免接受实际无效的 rc Tooltip 属性。#59288 @​QDyanbing
  • 🛎 修复 Drawer 未提示 destroyOnClose 已废弃的问题。#59299 @​dogledogle

6.6.4

  • 🗑 Deprecate legacy Avatar GroupProps, BackTop and FloatButton BackTopProps, Input GroupProps, Mentions OptionProps, and Select OptionProps types in favor of GetProps or option-derived types. #58949 @​li-jia-nan
  • 🐞 Fix AutoComplete missing classNames.clear and styles.clear semantic customizations for the clear button. #59245 @​lazerg
  • Table
    • 🐞 Fix Table filteredValue being ignored when responsive columns are hidden. #59198 @​QDyanbing
    • 🐞 Fix Table ignoring pagination.classNames and pagination.styles semantic customizations. #59267 @​QDyanbing
    • 🐞 Fix Table virtual cell content not being vertically centered. #59260 @​QDyanbing
  • Modal
    • 🐞 Fix Modal okText and cancelText falling back to default text for falsy ReactNode values. #59254 @​QDyanbing
    • 🐞 Fix Modal not triggering onCancel when cancelButtonProps.onClick is provided. #59255 @​QDyanbing
  • ColorPicker
    • 🐞 Fix ColorPicker clear control remaining interactive and showing hover styles when disabled. #59164 @​dogledogle
    • 🐞 Fix ColorPicker modifying presets and crashing when preset items are frozen. #59272 @​QDyanbing
  • 🐞 Fix Splitter panel sizes exceeding their min and max constraints when the container resizes. #59084 @​QDyanbing
  • 🐞 Fix Segmented selected item text color lagging behind the thumb animation when custom itemSelectedBg and itemSelectedColor tokens are used. #59046 @​EmilyyyLiu
  • 🐞 Fix Transfer restoring stale selections after dataSource item key types change. #59166 @​QDyanbing
  • 🐞 Fix FloatButton.Group menu flickering when moving the pointer from the trigger to the menu with trigger="hover". #59246 @​QDyanbing
  • 🐞 Fix Form vertical Form.Item controls shrinking inside horizontal layouts. #59263 @​QDyanbing
  • 🐞 Fix Tabs more dropdown ignoring styles.popup.root. #59221 @​giaBaoJS
  • 🐞 Fix ConfigProvider failing to inherit zeroRuntime in nested themes when inherit is false. #59250 @​QDyanbing

  • 🗑 废弃 Avatar GroupProps、BackTop 和 FloatButton BackTopProps、Input GroupProps、Mentions OptionProps 与 Select OptionProps 旧类型,建议改用 GetProps 或从选项推导的类型。#58949 @​li-jia-nan
  • 🐞 修复 AutoComplete 缺失清除按钮 classNames.clear 和 styles.clear 语义化配置的问题。#59245 @​lazerg

... (truncated)

Changelog

Sourced from antd's changelog.

6.6.5

2026-09-20

  • 🐞 Fix numeric 0 content rendering across Result, message, notification, Avatar, Modal, Descriptions, and Form.Item. #59153 #59125 #59289 @​bhumin18 @​nrps9909 @​QDyanbing
  • Upload
    • 🐞 Fix Upload.Dragger custom style.height being overridden when the height prop is not set. #59319 @​dogledogle
    • ♿ Fix Upload file names being focusable as buttons when no preview action is available. #59295 @​QDyanbing
  • Transfer
    • 🐞 Fix Transfer calling a stale onSelectChange callback after it is replaced or removed. #59307 @​yunfeizhu
    • 🐞 Fix Transfer footer callbacks not receiving direction when using rest parameters. #59303 @​QDyanbing
  • 🐞 Fix Avatar not retrying image loading after srcSet changes. #59297 @​QDyanbing
  • 🐞 Fix Anchor scrolling and Table and Transfer range selection using stale values after updates. #59308 @​QDyanbing
  • 🐞 Fix Select inconsistent single and multiple heights after customizing global fontSize or lineHeight. #59298 @​zombieJ
  • 🤖 Fix Tooltip, Popover, Popconfirm, and Slider TypeScript definitions accepting unsupported rc Tooltip props. #59288 @​QDyanbing
  • 🛎 Fix Drawer not warning that destroyOnClose is deprecated. #59299 @​dogledogle

6.6.4

2026-09-14

  • 🗑 Deprecate legacy Avatar GroupProps, BackTop and FloatButton BackTopProps, Input GroupProps, Mentions OptionProps, and Select OptionProps types in favor of GetProps or option-derived types. #58949 @​li-jia-nan
  • 🐞 Fix AutoComplete missing classNames.clear and styles.clear semantic customizations for the clear button. #59245 @​lazerg
  • Table
    • 🐞 Fix Table filteredValue being ignored when responsive columns are hidden. #59198 @​QDyanbing
    • 🐞 Fix Table ignoring pagination.classNames and pagination.styles semantic customizations. #59267 @​QDyanbing
    • 🐞 Fix Table virtual cell content not being vertically centered. #59260 @​QDyanbing
  • Modal
    • 🐞 Fix Modal okText and cancelText falling back to default text for falsy ReactNode values. #59254 @​QDyanbing
    • 🐞 Fix Modal not triggering onCancel when cancelButtonProps.onClick is provided. #59255 @​QDyanbing
  • ColorPicker
    • 🐞 Fix ColorPicker clear control remaining interactive and showing hover styles when disabled. #59164 @​dogledogle
    • 🐞 Fix ColorPicker modifying presets and crashing when preset items are frozen. #59272 @​QDyanbing
  • 🐞 Fix Splitter panel sizes exceeding their min and max constraints when the container resizes. #59084 @​QDyanbing
  • 🐞 Fix Segmented selected item text color lagging behind the thumb animation when custom itemSelectedBg and itemSelectedColor tokens are used. #59046 @​EmilyyyLiu
  • 🐞 Fix Transfer restoring stale selections after dataSource item key types change. #59166 @​QDyanbing
  • 🐞 Fix FloatButton.Group menu flickering when moving the pointer from the trigger to the menu with trigger="hover". #59246 @​QDyanbing
  • 🐞 Fix Form vertical Form.Item controls shrinking inside horizontal layouts. #59263 @​QDyanbing
  • 🐞 Fix Tabs more dropdown ignoring styles.popup.root. #59221 @​giaBaoJS
  • 🐞 Fix ConfigProvider failing to inherit zeroRuntime in nested themes when inherit is false. #59250 @​QDyanbing

6.6.3

2026-09-07

  • 🐞 Fix DatePicker and TimePicker rendering issues when prefix, suffixIcon, allowClear.clearIcon, or the value returned by renderExtraFooter is 0. #59212 react-component/picker#1009 @​github-actions @​QDyanbing
  • 🐞 Fix Modal and Drawer mask click closing behavior when reusing a mask configuration object. #59233 @​giaBaoJS
  • 🤖 Fix Select, AutoComplete, Cascader, and TreeSelect popupRender types to accept ReactElement and return ReactNode. #59207 @​QDyanbing
  • DatePicker
    • 🇩🇪 Fix DatePicker using incorrect default date and date-time formats with the German locale, using DD.MM.YYYY and DD.MM.YYYY HH:mm:ss respectively. #59151 @​nrps9909

... (truncated)

Commits
  • 4a39f54 chore(deps): update dependency size-limit to v14 (#59339)
  • 74f6318 chore(deps): update dependency dotenv to v18 (#59338)
  • 2baea10 docs: changelog for 6.6.5 (#59333)
  • 492d78e chore(deps): update codecov/codecov-action digest to 303a32d (#59334)
  • 050dd0e chore(deps): update jest dependencies to v30.5.2 (#59335)
  • 51dd67f chore(deps): update dependency @​size-limit/file to v14 (#59337)
  • fea0690 fix(demo): use prefixCls instead of token.antCls in Table demos (#59327)
  • e12b757 fix(demo): use public GetProps type in Avatar demo (#59328)
  • 91a6d1d chore(workflow): run upgrade deps at 08:00 Beijing time (#59322)
  • f045034 fix(Upload): keep Dragger style height when height prop is unset (#59319)
  • Additional commits viewable in compare view

Updates dompurify from 3.4.14 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

DOMPurify 3.4.15

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible
Commits

Updates marked from 18.0.11 to 18.0.14

Release notes

Sourced from marked's releases.

v18.0.14

…y with 13 updates

Bumps the production-dependencies group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@ant-design/icons](https://github.com/ant-design/ant-design-icons) | `6.3.2` | `6.3.4` |
| [@fission-ai/openspec](https://github.com/Fission-AI/OpenSpec) | `1.11.0` | `1.13.2` |
| [@inquirer/ansi](https://github.com/SBoudrias/Inquirer.js) | `2.0.7` | `2.0.8` |
| [@inquirer/core](https://github.com/SBoudrias/Inquirer.js) | `12.0.1` | `12.0.3` |
| [@inquirer/figures](https://github.com/SBoudrias/Inquirer.js) | `2.0.8` | `2.0.9` |
| [@inquirer/prompts](https://github.com/SBoudrias/Inquirer.js) | `8.7.0` | `8.7.2` |
| [@inquirer/type](https://github.com/SBoudrias/Inquirer.js) | `4.1.0` | `4.1.1` |
| [antd](https://github.com/ant-design/ant-design) | `6.6.2` | `6.6.5` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.14` | `3.4.16` |
| [marked](https://github.com/markedjs/marked) | `18.0.11` | `18.0.14` |
| [mermaid](https://github.com/mermaid-js/mermaid) | `11.17.2` | `12.0.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |



Updates `@ant-design/icons` from 6.3.2 to 6.3.4
- [Commits](https://github.com/ant-design/ant-design-icons/commits)

Updates `@fission-ai/openspec` from 1.11.0 to 1.13.2
- [Release notes](https://github.com/Fission-AI/OpenSpec/releases)
- [Changelog](https://github.com/Fission-AI/OpenSpec/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Fission-AI/OpenSpec/compare/v1.11.0...@fission-ai/openspec@1.13.2)

Updates `@inquirer/ansi` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/ansi@2.0.7...@inquirer/ansi@2.0.8)

Updates `@inquirer/core` from 12.0.1 to 12.0.3
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/core@12.0.1...@inquirer/core@12.0.3)

Updates `@inquirer/figures` from 2.0.8 to 2.0.9
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/figures@2.0.8...@inquirer/figures@2.0.9)

Updates `@inquirer/prompts` from 8.7.0 to 8.7.2
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.7.0...@inquirer/prompts@8.7.2)

Updates `@inquirer/type` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/type@4.1.0...@inquirer/type@4.1.1)

Updates `antd` from 6.6.2 to 6.6.5
- [Release notes](https://github.com/ant-design/ant-design/releases)
- [Changelog](https://github.com/ant-design/ant-design/blob/master/CHANGELOG.en-US.md)
- [Commits](ant-design/ant-design@6.6.2...6.6.5)

Updates `dompurify` from 3.4.14 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.14...3.4.16)

Updates `marked` from 18.0.11 to 18.0.14
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.11...v18.0.14)

Updates `mermaid` from 11.17.2 to 12.0.0
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.17.2...mermaid@12.0.0)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

---
updated-dependencies:
- dependency-name: "@ant-design/icons"
  dependency-version: 6.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@fission-ai/openspec"
  dependency-version: 1.13.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@inquirer/ansi"
  dependency-version: 2.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@inquirer/core"
  dependency-version: 12.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@inquirer/figures"
  dependency-version: 2.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@inquirer/prompts"
  dependency-version: 8.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@inquirer/type"
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: antd
  dependency-version: 6.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 18.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: mermaid
  dependency-version: 12.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@github-actions

Copy link
Copy Markdown

PR template needs attention

Please update this PR to match the current .github/PULL_REQUEST_TEMPLATE.md:

  • Missing template section: ## ✨ Summary
  • Missing template section: ## 🎯 Scope
  • Missing template section: ## 🧪 Testing
  • Missing template section: ## ✅ Checklist
  • Missing template section: ## 👀 Notes for Reviewers
  • Missing template item: CLI commands (init, status, doctor, update)
  • Missing template item: Core installer / platform detection
  • Missing template item: Comet skills (assets/skills/, assets/skills-zh/)
  • Missing template item: Comet shell scripts (assets/skills/comet/scripts/)
  • Missing template item: Tests / CI
  • Missing template item: Documentation / changelog
  • Missing template item: Other:
  • Missing template item: pnpm build
  • Missing template item: pnpm lint
  • Missing template item: pnpm run lint:architecture
  • Missing template item: pnpm format:check
  • Missing template item: pnpm test
  • Missing template item: pnpm test -- test/domains/comet-classic/comet-scripts.test.ts
  • Missing template item: Not run:
  • Missing template item: PR title follows Conventional Commits, for example fix: handle project-scope init
  • Missing template item: User-facing behavior is documented in README.md, README-zh.md, or CONTRIBUTING.md
  • Missing template item: CHANGELOG.md is updated when behavior changes
  • Missing template item: Skill changes were made in Chinese first when applicable, then synced to English
  • Missing template item: New scripts are included in assets/manifest.json and relevant tests
  • Missing template item: Shell scripts remain portable across macOS, Linux, and Windows Git Bash
  • Missing template item: No unrelated generated files or local artifacts are included
  • Checklist item is not checked: PR title follows Conventional Commits, for example fix: handle project-scope init
  • Checklist item is not checked: User-facing behavior is documented in README.md, README-zh.md, or CONTRIBUTING.md
  • Checklist item is not checked: CHANGELOG.md is updated when behavior changes
  • Checklist item is not checked: Skill changes were made in Chinese first when applicable, then synced to English
  • Checklist item is not checked: New scripts are included in assets/manifest.json and relevant tests
  • Checklist item is not checked: Shell scripts remain portable across macOS, Linux, and Windows Git Bash
  • Checklist item is not checked: No unrelated generated files or local artifacts are included

@github-actions

Copy link
Copy Markdown

👋 Thanks for opening your first PR to Comet, @dependabot[bot].

Before review, please make sure the PR title follows Conventional Commits, for example fix: handle project-scope init, and that the checklist in the PR template is up to date.

🧪 The most useful local checks are:

pnpm build
pnpm lint
pnpm format:check
pnpm test

🧰 If your change touches assets/skills/comet/scripts/, please also check script portability across macOS, Linux, and Windows Git Bash. Avoid sed -i, support both sha256sum and shasum -a 256, and guard optional grep pipelines with || true.

✨ We appreciate the contribution and will take a look as soon as we can.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 6ebd3424-04f7-4f34-ad4f-f2a66d98ebeb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants